StackRadar

CVE-2026-34757

Medium

Advisory

Published 9 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.1
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
761
of 17,787 indexed, latest versions
Container images
699
deployed by those charts
Fix available
4 of 4
affected packages

Security update for libpng16

Carried by container images the latest versions of 761 of 17,787 indexed charts deploy, on 699 images.

Affected packageAffected versionsFixed inImages
libpng1.6deb1.6.34-1ubuntu0.18.04.1, 1.6.34-1ubuntu0.18.04.2, 1.6.37-2, 1.6.37-3build5+14 more1.6.34-1ubuntu0.18.04.2+esm3, 1.6.37-2ubuntu0.1~esm3, 1.6.37-3ubuntu0.5, 1.6.39-2+deb12u5+3 more532
libpngdeb1.2.50-1ubuntu2, 1.2.50-1ubuntu2.14.04.2, 1.2.50-1ubuntu2.14.04.3, 1.2.54-1ubuntu1+1 more1.2.50-1ubuntu2.14.04.3+esm2, 1.2.54-1ubuntu1.1+esm320
libpngapk1.6.43-r0, 1.6.44-r0, 1.6.45-r0, 1.6.47-r0+4 more1.6.57-r0146
libpng16rpm1.6.40-150600.1.31.6.40-150600.3.20.11
OSV records
ALPINE-CVE-2026-34757DEBIAN-CVE-2026-34757UBUNTU-CVE-2026-34757SUSE-SU-2026:1602-1
Also known as
USN-8251-1, USN-8639-1

Charts affected

761 by stars
ChartLatestAffected imagesRadar Score
squawkvojtechpastyrikVerified publisher0.1.101 of 1See more

squawk vojtechpastyrik 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
libpng@1.6.55-r0
1.6.57-r0

Open the chart page →

400
kongwallarmVerified publisher4.6.31 of 7See more

kong wallarm 4.6.3

1 of the 7 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

11,444
pageswalter1.0.02 of 3See more

pages walter 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
flyway/flyway:6.4.422d97ceb0c47
libpng1.6@1.6.34-1ubuntu0.18.04.2
1.6.34-1ubuntu0.18.04.2+esm3

Open the chart page →

20,233
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

8,858
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

14,420
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

28,699
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

9,296
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3

Open the chart page →

6,323
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5

Open the chart page →

14,172
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
libpng1.6@1.6.39-2
1.6.39-2+deb12u5

Open the chart page →

7,685
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-34757.

Container imageDigestPackageFixed in
hamzaarshad10/queryfrontend:1.1.5.14cd359d9a78c3
libpng@1.6.44-r0
1.6.57-r0

Open the chart page →

13,197

Container images carrying it

699 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
libpng1.6@1.6.43-5ubuntu0.4
1.6.43-5ubuntu0.6
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
libpng1.6@1.6.43-5ubuntu0.4
1.6.43-5ubuntu0.6
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
zbalogh/reservation-angular-ui:1.0.95eb19e460b3c
libpng@1.6.47-r0
1.6.57-r0
1
zimengxiong/excalidash-frontend:0.4.27242629350b06
libpng@1.6.54-r0
1.6.57-r0
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
libpng@1.6.53-r0
1.6.57-r0
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
ghcr.io/appscode/deploy-ui:0.3.6f3e07eff3997
libpng@1.6.44-r0
1.6.57-r0
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
libpng1.6@1.6.48-1
1.6.48-1+deb13u5
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
ghcr.io/appscode/inbox-ui:0.0.5ae3b0e29daaa
libpng@1.6.47-r0
1.6.57-r0
1
ghcr.io/appscode/marketplace-ui:0.3.1d52177072013
libpng@1.6.44-r0
1.6.57-r0
1
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
ghcr.io/blessingnator/keycloak-mcn-frontend:2.0.1ddd462dbde39
libpng@1.6.55-r0
1.6.57-r0
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
libpng1.6@1.6.43-5ubuntu0.5
1.6.43-5ubuntu0.6
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/colanode/web:latestbcad696f03ee
libpng@1.6.47-r0
1.6.57-r0
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
libpng1.6@1.6.43-5ubuntu0.3
1.6.43-5ubuntu0.6
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
libpng1.6@1.6.48-1+deb13u1
1.6.48-1+deb13u5
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/dakera-ai/dakera-dashboard:0.3.292e059589f7f7
libpng@1.6.55-r0
1.6.57-r0
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
libpng1.6@1.6.48-1+deb13u3
1.6.48-1+deb13u5
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
libpng1.6@1.6.37-3build5
1.6.37-3ubuntu0.5
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
libpng1.6@1.6.48-1
1.6.48-1+deb13u5
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/element-hq/hydrogen-web:v0.5.12d15d14b201a
libpng@1.6.44-r0
1.6.57-r0
1
ghcr.io/ellite/wallos:2.46.09ce55520e7bd
libpng@1.6.44-r0
1.6.57-r0
1
ghcr.io/erlkoenig91/prompt-db-frontend:1.0.7121dc29eb14d
libpng@1.6.47-r0
1.6.57-r0
1
ghcr.io/esphome/esphome:2026.4.078a82d810709
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/ethpandaops/benchmarkoor-ui:latestd090bb2060d9
libpng@1.6.54-r0
1.6.57-r0
1
ghcr.io/ethpandaops/dispatchoor-web:latest18e30413dac2
libpng@1.6.54-r0
1.6.57-r0
1
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
libpng1.6@1.6.39-2
1.6.39-2+deb12u5
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
libpng1.6@1.6.43-5ubuntu0.5
1.6.43-5ubuntu0.6
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libpng1.6@1.6.37-2
1.6.37-2ubuntu0.1~esm3
1
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
libpng@1.6.44-r0
1.6.57-r0
1
ghcr.io/home-assistant/home-assistant:2025.12.59a5a3eb4a213
libpng@1.6.47-r0
1.6.57-r0
1
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
libpng@1.6.47-r0
1.6.57-r0
1
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
libpng@1.6.55-r0
1.6.57-r0
1
ghcr.io/home-operations/lidarr:3.1.29df1e14c8e09
libpng@1.6.56-r0
1.6.57-r0
1
ghcr.io/home-operations/lidarr:3.1.2.4902dab0e07502a3
libpng@1.6.53-r0
1.6.57-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.